The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateNOT REQUIRED
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factKEV
Assessment
This CVE remains in monitoring. Its metadata and source evidence are available below. A new material report or relevant sensor finding can trigger an AI review.
Why it matters
The available facts and source references are listed below. No AI assessment has been recorded for this dossier.
Evidence
No validated baseline evidence scope is persisted for this CVE.
Uncertainties
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
A validated functional exploit or automated exploitation capability would materially change this assessment.
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
CISA KEV lists this vulnerability as known to be exploited globally.
02
A proof of concept is reported; functional reliability is not established.
03
EPSS is 0.99; this is predictive context, not exploitation evidence.
04
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.
00:0010 Feb
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
05
Original publications
Source record
Greenbone Community FeedEXPLOIT INTELLIGENCEPRIMARY
Exploit tooling coverage changed for 7 CVEs
Greenbone Community Feed recorded exploit-tooling coverage changes for 7 CVEs in this pinned revision. 7 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.